Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-44310Criticalcom.liferay:com.liferay.layout.impl: Liferay Portal and Liferay DXP Vulnerable to XSS via the Page Tree MenuCVE-2023-42629Criticalcom.liferay:com.liferay.asset.categories.admin.web: Liferay Portal and Liferay DXP Vulnerable to Stored XSS in the Manage Vocabulary PageCVE-2023-44309Criticalcom.liferay:com.liferay.fragment.entry.processor.impl: Liferay Portal and Liferay DXP Vulnerable to XSS in the Fragment ComponentsCVE-2023-42497Criticalcom.liferay:com.liferay.translation.web: Liferay Portal and Liferay DXP Vulnerable to Reflected XSS via the Export for Translation PageCVE-2023-45138Criticalorg.xwiki.contrib.changerequest:application-changerequest-ui: XWiki Change Request Application UI XSS and remote code execution through change request titleCVE-2023-43667Highorg.apache.inlong:inlong: SQL Injection in Apache InLongCVE-2023-43668Criticalorg.apache.inlong:manager-pojo: Authorization Bypass in Apache InLongCVE-2023-43666Mediumorg.apache.inlong:inlong: Insufficient Verification of Data Authenticity in Apache InLongCVE-2023-44981Criticalorg.apache.zookeeper:zookeeper: Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeperGHSA-XPW8-RCWV-8F8PHighio.netty:netty-codec-http2: io.netty:netty-codec-http2 vulnerable to HTTP/2 Rapid Reset AttackCVE-2023-45648Mediumorg.apache.tomcat:tomcat: Apache Tomcat Improper Input Validation vulnerabilityCVE-2023-44487Mediumgolang.org/x/net: HTTP/2 Stream Cancellation AttackCVE-2023-36478Highorg.eclipse.jetty.http2:http2-hpack: HTTP/2 HPACK integer overflow and buffer allocationCVE-2023-42795Mediumorg.apache.tomcat:tomcat: Apache Tomcat Incomplete Cleanup vulnerabilityCVE-2023-42794Mediumorg.apache.tomcat:tomcat-coyote: Apache Tomcat Incomplete Cleanup vulnerabilityCVE-2023-36566MediumMicrosoft.CommonDataModel.ObjectModel: Microsoft Common Data Model SDK Denial of Service VulnerabilityCVE-2023-25822Mediumcom.epam.reportportal:service-api: Denial of service vulnerability on creating a Launch with too many recursively nested elements in reportportalCVE-2023-43643Mediumorg.owasp.antisamy:antisamy: mXSS in AntiSamyCVE-2023-45303Highorg.thingsboard:thingsboard: ThingsBoard Server-Side Template InjectionCVE-2023-36820Mediumio.micronaut.security:micronaut-security-oauth2: io.micronaut.security:micronaut-security-oauth2 has invalid IdTokenClaimsValidator logic on audCVE-2023-1584Highio.quarkus:quarkus-oidc: Quarkus OIDC can leak both ID and access tokensGHSA-86Q5-QCJC-7PV4Highcom.facebook.presto:presto-jdbc: Presto JDBC Server-Side Request Forgery by nextUriGHSA-XM7X-F3W2-4HJMHighcom.facebook.presto:presto-jdbc: Presto JDBC Server-Side Request Forgery by redirectCVE-2023-39410Highorg.apache.avro:avro: Apache Avro Java SDK vulnerable to Improper Input ValidationCVE-2023-3223Highio.undertow:undertow-parent: Undertow vulnerable to denial of service

Stop the waste.
Protect your environment with Kodem.